Cisco Patches Multiple Critical IOS XE Software Vulnerabilities
Cisco has released a critical security hardening update for its IOS XE Software to fix multiple serious vulnerabilities that could expose enterprise network devices to remote attacks.
The advisory covers vulnerabilities identified during Cisco's internal security testing, including testing supported by frontier AI models.
The most severe issue is CVE-2026-20272, which carries a maximum CVSS score of 9.8 out of 10 and can lead to command injection, operating system injection, or argument injection risks.
Cisco also addressed CVE-2026-20267, an improper access control issue rated 9.0, and several other vulnerabilities with a maximum CVSS score of 8.6.
The company strongly recommends affected organizations immediately upgrade to fixed software releases, as outlined in advisory cisco-sa-hardening-iosxe-V8NMuMZJ published on August 5, 2026.